2,047 known vulnerabilities affecting google products.
Products
Vulnerabilities by priority
| CVE | Priority | EPSS | CVSS | KEV | What |
|---|---|---|---|---|---|
| CVE-2026-58699 | Medium | 0.1% | 8.4 | In Vp9DecEndOfStream of vp9hwd_output.cc, there is a possible out-of-bounds read… | |
| CVE-2026-0100 | Medium | 0.1% | 7.8 | In Load of LoadedArsc.cpp, there is a possible out of bounds write due to a heap… | |
| CVE-2026-28593 | Medium | 0.1% | 7.8 | In getItemList of SettingsFragment.java, there is a possible user interaction by… | |
| CVE-2026-56985 | Medium | 0.1% | 8.4 | In multiple files, there is a possible way to obtain signatures due to type conf… | |
| CVE-2026-56986 | Medium | 0.1% | 8.4 | In multiple files, there is a possible out-of-bounds read due to type confusion.… | |
| CVE-2026-0093 | Medium | 0.1% | 7.8 | In multiple locations, there is a possible misleading UI due to obfuscation. Thi… | |
| CVE-2026-0096 | Medium | 0.1% | 7.8 | In getAppLabel of ForgetDeviceDialogFragment.java, there is a possible trick the… | |
| CVE-2026-28580 | Medium | 0.1% | 7.8 | In multiple functions, there is a possible desync in persistence due to an incor… | |
| CVE-2026-28653 | Medium | 0.1% | 7.8 | In multiple functions of rw_t3t.cc, there is a possible out of bounds write due … | |
| CVE-2026-57014 | Medium | 0.1% | 7.8 | In phNxpNciHal_ext_process_nfc_init_rsp of phNxpNciHal_ext.cc, there is a possib… | |
| CVE-2026-58695 | Medium | 0.1% | 7.8 | In gmc_phy_lp3_exit_restore_registers of phy_power.c, there is a possible escala… | |
| CVE-2025-32348 | Medium | 0.1% | 7.8 | In multiple locations, there is a possible background activity launch due to a m… | |
| CVE-2025-48570 | Medium | 0.1% | 7.8 | In multiple functions of PipTaskOrganizer.java, there is a possible way to launc… | |
| CVE-2026-0036 | Medium | 0.1% | 7.8 | In startAnimation of StageCoordinator.java, there is a possible tapjacking issue… | |
| CVE-2026-28613 | Medium | 0.1% | 7.3 | In initAppLinkTypeAndIntent of ChannelImpl.java, there is a possible launch an a… | |
| CVE-2026-28657 | Medium | 0.1% | 7.8 | In onActivityResult of AppWidgetConfigActivityProxy.java, there is a possible un… | |
| CVE-2026-58766 | Medium | 0.1% | 7.8 | In multiple functions of arm-smmu-v3.c, there is a possible escalation of privil… | |
| CVE-2025-48564 | Medium | 0.1% | 7.0 | In multiple locations, there is a possible intent filter bypass due to a race co… | |
| CVE-2026-0099 | Medium | 0.1% | 7.8 | In onNullBinding of HostEmulationManager.java, there is a possible way to launch… | |
| CVE-2026-28656 | Medium | 0.1% | 7.3 | In multiple functions of DeviceAdminAdd.java, there is a possible way to an over… | |
| CVE-2026-28602 | Medium | 0.1% | 7.8 | In setClipboardAccessNotificationsEnabledForUser of ClipboardService.java, there… | |
| CVE-2025-26418 | Medium | 0.1% | 7.8 | In setUserDisclaimerAcknowledged of CarDevicePolicyService.java, there is a poss… | |
| CVE-2026-0098 | Medium | 0.1% | 7.8 | In getCallingPackageName of Shared.java, there is a possible way to bypass activ… | |
| CVE-2026-28607 | Medium | 0.1% | 7.8 | In multiple functions in multiple locations, there is a possible background acti… | |
| CVE-2026-28614 | Medium | 0.1% | 7.8 | In onCreate of SlicePermissionActivity.java, there is a possible permission bypa… | |
| CVE-2026-28620 | Medium | 0.1% | 7.8 | In multiple locations, there is a possible unauthorized URI access due to a perm… | |
| CVE-2026-28631 | Medium | 0.1% | 7.8 | In buildMiniResolver of IntentForwarderActivity.java, there is a possible consen… | |
| CVE-2026-28636 | Medium | 0.1% | 7.8 | In setupLayout of PickActivity.java, there is a possible bypass of the "Install … | |
| CVE-2026-28644 | Medium | 0.1% | 7.8 | In startNextMatchingActivity of ActivityTaskManagerService.java, there is a poss… | |
| CVE-2026-58744 | Medium | 0.1% | 7.8 | In multiple locations, there is a possible escalation of privilege due to improp… | |
| CVE-2026-0089 | Medium | 0.1% | 7.8 | In multiple functions of PackageInstallerService.java, there is a possible way t… | |
| CVE-2026-0091 | Medium | 0.1% | 7.8 | In multiple locations, there is a possible way to execute code in the launcher p… | |
| CVE-2026-28572 | Medium | 0.1% | 7.8 | In onCreate of InstallLaunch.kt, there is a possible misleading UI due to a tapj… | |
| CVE-2026-28577 | Medium | 0.1% | 7.8 | In addWindow of WindowManagerService.java, there is a possible tapjacking issue … | |
| CVE-2026-28600 | Medium | 0.1% | 7.8 | In onCreate of PaymentDefaultDialog.java, there is a possible way to change defa… | |
| CVE-2026-28603 | Medium | 0.1% | 7.8 | In assertSafeToStartCustomActivity of AppRestrictionsFragment.java, there is a p… | |
| CVE-2026-28611 | Medium | 0.1% | 7.8 | In multiple functions of NfcService.java, there is a possible silent payment ses… | |
| CVE-2026-28616 | Medium | 0.1% | 7.8 | In Setup Wizard, there is a possible way to force connection to a malicious netw… | |
| CVE-2026-28624 | Medium | 0.1% | 7.8 | In multiple locations, there is a possible read/write access to files without th… | |
| CVE-2026-28626 | Medium | 0.1% | 7.3 | In onCreate of SetupPassthroughActivity.java, there is a possible way to launch … | |
| CVE-2026-0094 | Medium | 0.1% | 7.8 | In getApplicationLabel of KeyChainActivity.java, there is a possible way to tric… | |
| CVE-2026-58701 | Medium | 0.1% | 7.0 | In trusty_dputc of generic-arm64-smcall.c, there is a possible out-of-bounds wri… | |
| CVE-2026-58724 | Medium | 0.1% | 7.0 | In multiple locations, there is a possible use-after-free due to a race conditio… | |
| CVE-2026-58728 | Medium | 0.1% | 7.0 | In ARM64_TLBI of mmu.h, there is a possible memory corruption due to a race cond… | |
| CVE-2026-58734 | Medium | 0.1% | 7.0 | In google_mba_recv_msg of google_mba_poll.c, there is a possible out-of-bounds w… | |
| CVE-2026-28590 | Medium | 0.1% | 7.8 | In multiple locations, there is a possible improper encryption key validation du… | |
| CVE-2021-26439 | Low | 2.9% | 4.6 | Microsoft Edge for Android Information Disclosure Vulnerability | |
| CVE-2021-38641 | Low | 1.2% | 6.1 | Microsoft Edge for Android Spoofing Vulnerability | |
| CVE-2020-26964 | Low | 0.9% | 6.8 | If the Remote Debugging via USB feature was enabled in Firefox for Android on an… | |
| CVE-2026-17664 | Low | 0.6% | 6.5 | Insufficient validation of untrusted input in Loader in Google Chrome prior to 1… |